Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-03 · updated: 2026-10-03 · tags: [incident, retail] · confidence: high · severity: low · affected_sectors: [retail] · au_impact: false

Unknown attackers hijacked the official Microsoft account on X (formerly Twitter), which has more than 13 million followers, and used it on 1 October to promote what appeared to be a cryptocurrency pump-and-dump scheme. The attack began when the Microsoft account followed and reposted a tweet from an impersonating account (@clippymsftcto) centred on Microsoft's Clippy virtual assistant; while that account was suspended, a related account (@ClippyMSFT) was still promoting a $Clippy token claiming a liquidity pool paired directly with "$MSFT". Microsoft removed the attackers' posts and, through a spokesperson, confirmed unauthorised access, said the account had been secured and the unauthorised posts removed, and that the circumstances continue under investigation. In a now-deleted tweet the company apologised, said it does not support any cryptocurrency or crypto-related token, and said it would take legal action. Microsoft separately said no Clippy or Microsoft-branded token is authorised and that it will pursue legal action to remove the unauthorised token. It is not the first time a Microsoft X account has been compromised for crypto scams — the Microsoft India account was similarly hijacked in June 2024.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-10-03
Source BleepingComputer
Reliability Tier 2